The KEV bar
The vast majority of disclosed vulnerabilities are never exploited in the wild. The KEV catalog is the short, high-signal list of CVEs with confirmed exploitation evidence — the ones that change a remediation priority.
Patching what matters
Because KEV entries carry binding remediation deadlines, they convert vulnerability data into an operational directive: patch these, in this order, now. That is why H3XA surfaces KEV context directly on vulnerability objects.
What this means
When a vulnerability appears in H3XA with KEV context, treat it differently from the surrounding corpus. It is not merely disclosed — it is being used.